Sceawere

Vulnerability Detail

CVE-2026-72798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Attribute View Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
2h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-08-12T20:17:51.543Z",
  "pubdate": "2026-08-12T20:17:51.543Z",
  "executiveSummary": "A security vulnerability affecting SiYuan versions prior to v3.7.4 involves improper input filtering of related-database content within the renderAttributeView component.\nThe vulnerability allows anonymous readers to bypass access controls and retrieve sensitive data from hidden or password-protected databases, including Relation and Rollup cell contents.\nAdditionally, attackers can bypass row-level filtering mechanisms entirely under specific structural conditions, such as when the first column is a non-block type.\nThe risk implication is unauthorized exposure of sensitive internal data and confidentiality breaches across protected document spaces.\nAttackers require network access to the target instance and the ability to craft specific database relationship requests, but no authentication or specialized privileges are required to exploit the flaw.",
  "technicalDetails": "The root cause of the vulnerability resides in the insufficient validation and filtering logic implemented within the renderAttributeView function of SiYuan prior to version v3.7.4.\nThe vulnerable component fails to adequately verify access permissions for related-database content, treating cross-database references insecurely when processing attribute views.\nAffected versions include all SiYuan deployments prior to v3.7.4.\nThe vulnerability requires no authentication or specific user privileges, exposing the flaw over the network to anonymous readers.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies or queries published databases that maintain relationships with restricted, hidden, or password-protected databases. Second, the attacker issues crafted requests leveraging these relationships to traverse the database boundary. Third, the rendering engine processes the attribute views and fails to redact Relation and Rollup cell contents originating from the restricted databases, returning the sensitive data directly in the response.\nFurthermore, exploitation can occur when an attacker targets row filtering mechanisms. If the first column of the targeted database view is configured as a non-block type, the filtering logic fails to evaluate row constraints correctly, allowing attackers to bypass row filtering entirely and access unauthorized records.\nThe post-exploitation impact includes the total compromise of confidentiality for data contained within hidden or password-protected rollups and relations, as well as unauthorized traversal of row-restricted database content by unauthenticated actors."
}
CVE-2026-72798: SiYuan Attribute View Information Disclosure (HIGH Severity, CVSS: 8.6) - Sceawere